A cloud-native SIEM solution that provides intelligent security analytics and threat detection across systems
I figured out another way. You don't need a tenant governance relationship. If you have GDAP then you can assign Azure roles to the remote tenant groups. NO tenant governance relationship required.
Everything works but when I click on tables in Sentinel in Defender I can't get it to load.
Then I see weird 403's when I inspect the page.
Request URL from inspection - https://security.microsoft.com/apiproxy/tm/tableManagement/public/transformations?$filter={Redacted}
Response -
{
"error": {
"code": "Forbidden",
"message": "Requestor context is not available.",
"details": []
}
}
Did Microsoft forget to make "Tables" compatible with GDAP for Sentinel in Defender?
Can anyone try?